Alerte – 50 plugins WordPress troués !Développeurs pas au top...
- Homepage slideshow-3D banner rotator- Nmedia User File Uploader
- Front end upload- Poverplay gallery- WordPress Accordion Gallery- Wp superb slideshow
- Wp-Property- Video Gallery 1.3- HTML5 Av Manager- Royal Gallery
- 3D Flick Slideshow- Image News Slider- RBX Gallery- wp-gpx-map
- File groups- User Meta- SfBrowser- WPStoreCart- Hungred Post Thumbnail
- MM Forms Community- Tinymce Remind- Gallery- Thinkun Remind
- Foxypress- PDW File Browser- VideoWhisper- WordPress Font Uploader
- FCChat Widget- Comment Extra Fields- Nmedia WordPress Member Conversation
- PictureSurf Gallery- Really simple Gallery (probably vuln)- PICA Photo Gallery
- Asset Manager- Vertical slideshow- Carousel slideshow- Front file manager
- Omni secure files- Mac photo gallery- Smart slideshow- Bliss Galery- YASS
- Catpro Gallery- Matrix Gallery- Gallery Explorer- Dreamwork Gallery- Blaze slideshow- Slideshow pro
Pour se protéger, plusieurs possibilités à part virer le plugin vulnérable:
Placer un fichier .htaccess dans les dossiers de plugin
Placer des index.php vides dans les dossiers qui n'en ont pas
Inclure un appel aux variables ABSPATH ou session admin au début de chaque script php
source :
http://korben.info/